Linux SCSI subsystem development
 help / color / mirror / Atom feed
From: John Garry <john.garry@linux.dev>
To: Bart Van Assche <bvanassche@acm.org>,
	"Martin K . Petersen" <martin.petersen@oracle.com>
Cc: linux-scsi@vger.kernel.org, Christoph Hellwig <hch@lst.de>
Subject: Re: [PATCH 1/7] scsi: scsi_debug: Fix a locking bug in resp_write_same()
Date: Wed, 23 Sep 2026 08:44:01 +0100	[thread overview]
Message-ID: <9d1dc4e5-85e9-4126-8fd9-30e0b5b47dda@linux.dev> (raw)
In-Reply-To: <41890e94-10da-4b99-af6d-35106b88f026@linux.dev>

On 9/23/26 08:37, John Garry wrote:
> On 9/23/26 00:26, Bart Van Assche wrote:
>> If fetch_to_dev_buffer() fails in resp_write_same(), the function jumps
>> to 'out' without releasing the data write lock acquired earlier via
>> sdeb_data_write_lock(). Jump to 'unlock' instead so that
>> sdeb_data_write_unlock() is called on the error path. This bug has been
>> discovered by building the scsi_debug driver with Clang and modified
>> lock context annotations. The modified lock context annotations are
>> available in patch "scsi: scsi_debug: Improve lock context annotations".
>>
>> Fixes: 84f3a3c01d70 ("scsi: scsi_debug: Atomic write support")
>> Signed-off-by: Bart Van Assche <bvanassche@acm.org>
>> ---
>>   drivers/scsi/scsi_debug.c | 3 ++-
>>   1 file changed, 2 insertions(+), 1 deletion(-)
>>
>> diff --git a/drivers/scsi/scsi_debug.c b/drivers/scsi/scsi_debug.c
>> index 6941809dfdb7..b854102e6caa 100644
>> --- a/drivers/scsi/scsi_debug.c
>> +++ b/drivers/scsi/scsi_debug.c
>> @@ -5402,7 +5402,7 @@ static int resp_write_same(struct scsi_cmnd 
>> *scp, u64 lba, u32 num,
>>       if (-1 == ret) {
>>           ret = DID_ERROR << 16;
>> -        goto out;
>> +        goto unlock;
> 
> at @unlock we lose the error code in ret - is that intentional?
> 

Now I notice that sashiko spotted this too. I will await until issues 
spotted by sashiko elsewhere at attended to before checking further.

>>       } else if (sdebug_verbose && !ndob && (ret < lb_size))
>>           sdev_printk(KERN_INFO, scp->device,
>>                   "%s: %s: lb size=%u, IO sent=%d bytes\n",
>> @@ -5419,6 +5419,7 @@ static int resp_write_same(struct scsi_cmnd 
>> *scp, u64 lba, u32 num,
>>       /* If ZBC zone then bump its write pointer */
>>       if (sdebug_dev_is_zoned(devip))
>>           zbc_inc_wp(devip, lba, num);
>> +unlock:
>>       sdeb_data_write_unlock(sip);
>>       ret = 0;
>>   out:
> 


  reply	other threads:[~2026-09-23  7:44 UTC|newest]

Thread overview: 16+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-22 23:26 [PATCH 0/7] scsi_debug: Enable lock context analysis Bart Van Assche
2026-09-22 23:26 ` [PATCH 1/7] scsi: scsi_debug: Fix a locking bug in resp_write_same() Bart Van Assche
2026-09-22 23:32   ` sashiko-bot
2026-09-23  7:37   ` John Garry
2026-09-23  7:44     ` John Garry [this message]
2026-09-23 19:39     ` Bart Van Assche
2026-09-22 23:26 ` [PATCH 2/7] scsi: scsi_debug: Split resp_write_same() Bart Van Assche
2026-09-22 23:38   ` sashiko-bot
2026-09-22 23:26 ` [PATCH 3/7] scsi: scsi_debug: Split corrupt_lbas() Bart Van Assche
2026-09-22 23:26 ` [PATCH 4/7] scsi: scsi_debug: Split resp_read_dt0() Bart Van Assche
2026-09-22 23:37   ` sashiko-bot
2026-09-22 23:26 ` [PATCH 5/7] scsi: scsi_debug: Split resp_write_dt0() Bart Van Assche
2026-09-22 23:41   ` sashiko-bot
2026-09-22 23:26 ` [PATCH 6/7] scsi: scsi_debug: Improve lock context annotations Bart Van Assche
2026-09-22 23:41   ` sashiko-bot
2026-09-22 23:26 ` [PATCH 7/7] scsi: core: Enable lock context analysis for the scsi_debug driver Bart Van Assche

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=9d1dc4e5-85e9-4126-8fd9-30e0b5b47dda@linux.dev \
    --to=john.garry@linux.dev \
    --cc=bvanassche@acm.org \
    --cc=hch@lst.de \
    --cc=linux-scsi@vger.kernel.org \
    --cc=martin.petersen@oracle.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox